logo

FalconHound, attack path management for blue teams

ID: 30bc7c96-0f33-5417-a4f5-b3a27cb49781

STIX ID: report--30bc7c96-0f33-5417-a4f5-b3a27cb49781

Feed Name: FalconForce

Date Published: 2023-11-10

Date Updated: 2026-04-27

Author: Olaf Hartong

...
...

This blog introduces FalconHound, a Golang-based tool that enriches BloodHound with near-real-time data from sources like Microsoft Sentinel, Defender for Endpoint, Splunk, Microsoft Graph, and Neo4j to help blue teams manage attack paths. It uses configurable actions to ingest log events (e.g., logons, role changes), create/update graph edges (including a new HadSession concept), and tag assets as owned, exploitable, or exposed. The enriched graph data can drive detections, watchlists, and analyst queries, enabling prioritization and lateral movement insights, while complementing periodic SharpHound/AzureHound collections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.